ShopVisible: Blogs
 
ECommerce Blog By ShopVisible
ECommerce Blog by Tag: CDE
RSS
Include comments
TAG CLOUD
404 Error A B testing abandoned carts abandonment rates Alexa amazon analytics Atlanta eCommerce Atlanta Piano vendors Atlanta SEO authenteak auto dealer Auto Leasing auto-complete Automotive ecommerce Bambeco baseball caps baseball hats blackberry cases brand awareness online brick and mortar retailers bugs Car Dealers Car Dealerships cars miami Case Mate case-mate CCart of the Week CDE cell phone cases channel integraion classic cars florida classic cars miami CMS Cnet content management controlScan cookies coupon Coupons craigslist creativity Credibility customer reviews cyber security d terrell David Taylor Dealerships design domain donell DonL ECommerce ecommerce platform Ecommerce solution google Internet Retailer PCI SEO ShopBags shopvisible ted vernon URL
 
RECENT POSTS
USA Today Takes Notice of ShopVisible's Facebook Application
  Comments: 0
  Rating: 0 / 0
Retailers: 50% Off Two Main Days at Etail West Courtesy of ShopVisible
  Comments: 0
  Rating: 0 / 0
ShopVisible Powers Internet Retailer's Hot 100
  Comments: 0
  Rating: 0 / 0
ShopVisible Launches PayLessDecor.com
  Comments: 0
  Rating: 0 / 0
PCI/Security Expert David Taylor Passes Away
  Comments: 0
  Rating: 0 / 0
ShopBags.com Featured in Chain Store Age Magazine
  Comments: 0
  Rating: 0 / 0
ShopVisible and Payless Décor Featured on InternetRetailer.com
  Comments: 0
  Rating: 0 / 0
Ecommerce Security: PCI, Risk and Cost
  Comments: 0
  Rating: 0 / 0
SaaS-based CyberSecurity: Ecommerce and PCI Options
  Comments: 0
  Rating: 0 / 0
SEO Awesomeness: RightSize Online
  Comments: 0
  Rating: 0 / 0
 
RECENT COMMENTS
No Comments Available
 
ARCHIVES
2010
 February (1)
 January (1)
 
2009
 December (1)
 November (3)
 October (4)
 September (6)
 August (7)
 July (7)
 June (3)
 May (5)
 April (3)
 March (2)
 February (2)
 January (3)
 
 
AUTHORS
BC (2)
Bharat C (2)
DannieB (34)
e-commerce info (1)
E-Commerce Information (1)
Emma G (1)
jvm (20)
Nithya (1)
SEO Information (1)
The Frog (4)
Webster J Frogg (10)
 
CATEGORIES
 
BLOG ROLL
Feed Growth!
 
PCI 2010 and Beyond: Ecommerce Security News
By JVM 9/9/2009 11:42:00 AM
For many Ecommerce merchants processing orders and maintaining a website is an immense time-consuming step to growing a business. Grappling with PCI compliance and delving deeper into its origins, existence and proliferation are another daunting task to say the least.

Recently the NRF or National Retail Federation issued a merchant survey investigating PCI compliance and small online retailers. Out the polled group, 19% of non-compliant merchants said they had little to no understanding of this payment security process that is becoming increasingly imperative today in Ecommerce. Another 26% stated they lacked “the financial or technical resources to meet the standard, which covers a dozen broad areas from physical and network security to protecting” the CDE or cardholder data environment and maintaining commensurately structured security policies. Interestingly however, 86% of those polled claimed to feel somewhat familiar with PCI and its Ecommerce requirements.

A burgeoning problem for many merchants is that PCI standards evolve as do online threats and the emergence of security standards for making online transactions. New requirements are forced upon retailers in an effort to better protect cardholder spending money online. Analogously, PCI is implementing regulatory changes that will also affect payment processors and software providers. In summer 2010, new changes will occur that will dramatically affect both small online merchants and enterprise-size larger retailers alike.

-Pending PCI reqs.: any payment software handling cardholder data must comply with the PCI subset, Payment Application Data Security Standard…
-Pending PCI reqs.2: imposed by MasterCard, all merchants accepting credit cards online and in particular, those larger companies (level II merchants) must use 3rd party auditors to assess their PCI compliance

What does this mean? For starters, smaller merchants will be taking on increased spending in order to remain compliant. Further, larger merchants will have to be assessed by outside parties and done so in a more stringent manner than previous iterations of PCI compliance mandated.

So how can merchants, small or large, reduce the heightened cost of Ecommerce and PCI compliance? Internet Retailer and PCI KnowledgeBase advise not to store cardholder information if at all possible. Currently, under the PCI mandates, only “retailer systems, networks, servers, databases and software-that hold cardholder data fall under PCI.” Maintaining a strict and structured distance from the CDE will encourage PCI audit exclusion for Ecommerce merchants, small or large.


***Chart created from Internet Retailer, “Don’t Look Now.” Don Davis, Sept. 2009, p. 21***



PCI Level
Annual Transaction Volume
IR's no. of Merchants
Compliance Cost

1
6 million cc
362
$450,000-4,400,000

2
1-6 million cc
702
$77,500-470,000

3
20,000-1 million cc/Ecommerce payment
2634
$19,250-72,000

4
under 20,000 Ecommerce; under 1 million total
6 million
under $5000

Rates of Compliance:
1-93%
2-88%
3-57%
4-NA

ShopVisible is an Ecommerce solution based in Atlanta, GA.

Currently rated 0 by 0 people

Tags: ShopVisible, PCI compliance, Ecommerce solution, Ecommerce security, CDE, Internet Retailer, Atlanta SEO
Categories: SEO, RSS, User Generated Content
 
Comments(0) | Email this | RSS  

 
 
 
 
© 2010 SHOPVISIBLE ALL RIGHTS RESERVED